Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.802884
Kategorie:Buffer overflow
Titel:Symantec pcAnywhere 'awhost32' Remote Code Execution Vulnerability
Zusammenfassung:This host is running Symantec pcAnywhere and is prone to remote; code execution vulnerability.
Beschreibung:Summary:
This host is running Symantec pcAnywhere and is prone to remote
code execution vulnerability.

Vulnerability Insight:
The host services component 'awhost32' fails to filter crafted long
login and authentication data sent on TCP port 5631, which could be
exploited by remote attackers to cause a buffer overflow condition.

Vulnerability Impact:
Successful exploitation will allow attackers to cause buffer overflow
condition or execute arbitrary code or cause a denial of service condition.

Affected Software/OS:
Symantec pcAnywhere version 12.5.x through 12.5.3

Symantec pcAnywhere Solution shipped with Altiris IT Management Suite 7.0 (12.5.x)

Symantec pcAnywhere Solution shipped with Altiris IT Management Suite 7.1 (12.6.x)

Solution:
Upgrade to Symantec pcAnywhere 12.5 SP4 or pcAnywhere Solution 12.6.7
or Apply Symantec hotfix TECH182142.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Querverweis: BugTraq ID: 51592
Common Vulnerability Exposure (CVE) ID: CVE-2011-3478
http://www.securityfocus.com/bid/51592
https://www.exploit-db.com/exploits/38599/
http://osvdb.org/show/osvdb/78532
http://secunia.com/advisories/48092
Common Vulnerability Exposure (CVE) ID: CVE-2011-3479
BugTraq ID: 51593
http://www.securityfocus.com/bid/51593
Common Vulnerability Exposure (CVE) ID: CVE-2012-0292
BugTraq ID: 52094
http://www.securityfocus.com/bid/52094
http://www.exploit-db.com/exploits/18493/
Common Vulnerability Exposure (CVE) ID: CVE-2012-0291
BugTraq ID: 51965
http://www.securityfocus.com/bid/51965
CopyrightCopyright (C) 2012 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.